Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Operation DRBControl

Operation DRBControl

TLP:CLEAR
Active

Also known as: APT27, LotusBlossom, APT41, Winnti, Emissary Panda, APT10, LuckyMouse, EmissaryPanda, TG-3390, Bronze Union, Lucky Mouse

Description

Operation DRBControl is a cyberespionage campaign targeting gambling companies in Southeast Asia, first identified in 2019. The operation involves the use of HyperBro malware and SysUpdate variants, with evidence of customer database and source code exfiltration. The threat actor has employed domain spoofing for command and control and has shown a consistent interest in the gambling industry. Trend Micro's analysis linked multiple tools and malware families to this campaign, indicating a sophisticated and evolving threat landscape.

Goals & Targeting

Targeted Sectors

Government
Telecommunications
Energy
Financial services
Defense
Critical infrastructure
Aerospace
Manufacturing
Non profit
Healthcare
Retail
Media
Construction
Gaming
Aviation
Education
Think tank

Targeted Countries / Regions

US
CN
TW

AI Analysis

Grounded in web research
· analyzed in 4 chunks · 1 day ago

Executive Summary

Operation DRBControl is a high‑sophistication cyber‑espionage actor that uses a shared toolbox with groups such as Iron Tiger/APT27 and Winnti to conduct credential theft, data exfiltration, and ransomware delivery against government, critical infrastructure, and commercial targets in the United States, China, and Taiwan. The campaign relies on evolving backdoors (SysUpdate, HyperBro) that support both Windows and Linux, and it routinely leverages publicly known CVEs, DLL side‑loading abuses, and stolen certificates to evade defenses. While primarily focused on espionage, the group has also deployed ransomware in opportunistic attacks,

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.trendmicro.com — Cited by web research for: LuckyMouse
  2. apt.etda.or.th — Cited by web research for: TG-3390
  3. www.trendmicro.com — Cited by web research for: Custom malware

Intel Summary

0

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
Cyberespionage
Gambling Industry
Southeast Asia

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.